Sysmon - Non-ASCII character in the ParentUser and ParentCommandLine field
Has anyone seen this behavior with Sysmon: getting non-ASCII characters in the ParentUser, and ParentCommandLine fields? Sometimes it looks like another language character set, other times it is WingDings or some other non-sensical characters. This screenshot is from Splunk and is a screenshot of 2 devices over a 60 minute sampling window. Only happens with Event code = 1. Cannot determine a pattern and it is a rare event. In the last 24 hour period 10 events with this issue out of 895,000,000+.
The screenshot is from a Splunk query. I have verified that the non-ASCII characters are in the native Windows event logs BEFORE they are forwarded to Splunk.
Bob M.